INFORMATION SYSTEMS SECURITY MANAGER
Job summary
The Information Systems Security Manager is responsible for establishing, implementing and continuously improving the organization’s Information Security Management Framework. The role safeguards information assets, business systems, cloud services, enterprise applications, network security controls and digital services by providing strategic leadership in cybersecurity, firewall governance, endpoint security, identity and access management, ICT risk management, security compliance, incident response and business continuity.
Job descriptions & requirements
JOB TITLE INFORMATION SYSTEMS SECURITY MANAGER
NATURE OF JOB FULL TIME
INDUSTRY MANUFACTURING
SALARY KSHS.70,000-100,000
JOB LOCATION MLOLONGO
DUTIES AND RESPONSIBILITIES
Information Security Governance
· Develop and maintain the Information Security Strategy.
· Develop and review ICT security policies, standards and procedures.
· Maintain the Information Security Management Framework.
· Review security maturity and recommend improvements.
· Ensure security governance aligns with business objectives.
· Maintain ICT security documentation.
Cybersecurity
· Lead the enterprise cybersecurity programme.
· Coordinate vulnerability assessments and penetration testing.
· Monitor emerging cyber threats and recommend mitigation.
· Coordinate security incident response.
· Review malware, phishing and ransomware protection.
· Prepare monthly cybersecurity reports.
Firewall & Network Security
· Administer enterprise firewalls and security appliances.
· Approve firewall rule requests and conduct periodic rule reviews.
· Manage VPN security and remote access controls.
· Manage IDS/IPS policies.
· Monitor firewall logs and perimeter security events.
· Review network segmentation and internet security controls.
Endpoint Security
· Manage Endpoint Detection & Response (EDR).
· Ensure endpoint encryption and antivirus compliance.
· Develop endpoint hardening standards.
· Review endpoint vulnerabilities and coordinate remediation.
· Monitor endpoint compliance dashboards.
Identity & Access Management
· Manage identity governance and role-based access control.
· Approve privileged access requests.
· Conduct quarterly user access reviews.
· Enforce password and Multi-Factor Authentication policies.
· Ensure timely onboarding and offboarding of user accounts.
Risk, Audit & Compliance
· Maintain the ICT Risk Register.
· Conduct ICT security risk assessments.
· Coordinate ICT audits and implement corrective actions.
· Support regulatory and compliance reviews.
· Track audit findings to closure.
Business Continuity
· Support Business Continuity and Disaster Recovery planning.
· Coordinate Disaster Recovery security testing.
· Review backup security and ransomware readiness.
· Security Awareness
· Develop annual security awareness programmes.
· Conduct user security training.
· Coordinate phishing simulations and awareness campaigns.
Vendor Security
· Assess third-party security controls.
· Review cloud and hosted service security.
· Ensure vendor access is controlled and monitored.
Management
· Prepare departmental budgets and work plans.
· Provide security advice to management.
· Supervise security staff where applicable.
· Participate in ICT management meetings.
KEY REQUIREMENT SKILLS AND QUALIFICATION
· Degree in Computer Science, Information Technology, Information Systems or related field
· Minimum 5 years relevant ICT experience & 2 years in information security, infrastructure or ICT governance
· Strong understanding of information security governance and cybersecurity
· Knowledge of firewalls, VPNs, IDS/IPS, endpoint security and identity management
· Knowledge of ICT risk management and compliance
· Strong analytical and problem-solving skills
HOW TO APPLY
· If you meet the above qualifications, skills and experience share CV on recruitment@britesmanagement.com
· Interviews will be carried out on a rolling basis until the position is filled.
· Only the shortlisted candidates will be contacted.
Important safety tips
- Do not make any payment without confirming with the BrighterMonday Customer Support Team.
- If you think this advert is not genuine, please report it via the Report Job link below.